12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

2Using <strong>McAfee</strong> DLP MonitorFind data by time, transmission method, or locationFind data by time, transmission method, or locationAll objects are time‐stamped at the time of capture, and the ports and protocol through which they aretransmitted are known. Geographic locations and web sites are also recorded.Tasks• Search using time parameters on page 46Because of the volume of data captured, it is essential to define a time frame beforesearching. Every file is time‐stamped when it is added to one of the <strong>McAfee</strong> DLP databases.• Search by port on page 48Search by port to identify incidents by source, destination, or in both directions.• Search by port range on page 48Search by port range to identify incidents in a type of traffic by source, destination, orboth.• Search by excluding ports on page 49Exclude ports from a query to prevent incidents using them from appearing in searchresults.• Search by using protocols on page 50You can identify a specific type of traffic by using protocols as search qualifiers.• Search by excluding protocols on page 50Exclude protocols from a query to prevent incidents using them from appearing in searchresults.• Find incidents related to geographic locations and web sites on page 51Traffic to and from geographic locations or web sites might be reported in incidents.Search using time parametersBecause of the volume of data captured, it is essential to define a time frame before searching. Everyfile is time‐stamped when it is added to one of the <strong>McAfee</strong> DLP databases.Objects are time‐stamped in UTC Universal Coordinated Time at the moment they are captured innetwork traffic, found in file systems or databases, or generated as endpoint events. <strong>McAfee</strong> DLPsystems do conversion between local and global time automatically.For this reason, it is essential to set time frames for searches or rules, and to remember the date ofinstallation of a <strong>McAfee</strong> DLP appliance. The system cannot retrieve results that have not yet beenfound.If a time frame is set as a filter, any results reported as the result of a search or rule will be constrainedto that time frame. The filter must be cleared before the results outside of that time frame can beviewed.Tasks• Search for files by global time (GMT) on page 47When you set a Date/Time parameter in a search or rule, local time is automatically convertedto Greenwich Mean Time (GMT). This default allows you to find files that might betime‐stamped at or near the same time globally by creation, modification, or last accessedtimes.• Search in a relative time frame on page 47The search engine is able to locate files that are time‐stamped within a relative time frame.• Search by file creation time on page 47Search for files that were created at a particular time.• Search by file last modification time on page 48Search for files by the last time they were modified.46 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!